CVE-2024-32584: WordPress TeraWallet plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StandaloneTech TeraWallet – For WooCommerce allows Stored XSS.This issue affects TeraWallet – For WooCommerce: from n/a through 1.5.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32584?
CVE-2024-32584 is rated as a high-severity vulnerability due to the potential for stored XSS attacks.
How do I fix CVE-2024-32584?
To fix CVE-2024-32584, update the StandaloneTech TeraWallet plugin to version 1.5.1 or later.
What type of vulnerability is CVE-2024-32584?
CVE-2024-32584 is a Cross-site Scripting (XSS) vulnerability that allows for the improper neutralization of input during web page generation.
Which versions of TeraWallet are affected by CVE-2024-32584?
TeraWallet versions from any version before 1.5.1 up to and including 1.5.0 are affected by CVE-2024-32584.
What are the potential impacts of CVE-2024-32584?
If exploited, CVE-2024-32584 can lead to unauthorized actions being performed on behalf of users, potentially compromising user data.